Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:74095 - Security Advisory
Issued:
2026-09-30
Updated:
2026-09-30

RHSA-2026:74095 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: rsync security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for rsync is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.

Security Fix(es):

  • rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
  • rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
  • rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
  • rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
  • rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
  • rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
  • rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
  • rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
  • rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
  • rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
  • rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
  • rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)
  • rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)
  • rsync: rsync: Information disclosure and denial of service via crafted files-from entry (CVE-2026-70461)
  • rsync: rsync: Arbitrary File Read via Symlink Following (CVE-2026-53802)
  • rsync: rsync: Arbitrary file write via path traversal in --relative mode (CVE-2026-53785)
  • rsync: rsync: Directory escape via TOCTOU race condition in rrsync (CVE-2026-53783)

Bug Fix(es) and Enhancement(s):

  • Fix latest CVEs in rsync in RHEL8 (JIRA:RHEL-256903)
  • rsync-3.1.3-27.el8_10 regression: rsync daemon rejects legitimate cross-device symlinks with EXDEV when use chroot = no (JIRA:RHEL-239553)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x

Fixes

  • BZ - 2515368 - CVE-2026-70460 rsync: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
  • BZ - 2515375 - CVE-2026-53789 rsync: rsync: Arbitrary file deletion via malicious file list
  • BZ - 2515378 - CVE-2026-53790 rsync: rsync < 3.5.0 Command Injection via Multiple Code Paths
  • BZ - 2515379 - CVE-2026-70458 rsync: rsync: Memory corruption via crafted file entries
  • BZ - 2515380 - CVE-2026-70464 rsync: rsync: Denial of Service via handshake stall
  • BZ - 2515381 - CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following
  • BZ - 2515384 - CVE-2026-53784 rsync: rsync: Unauthorized File Access via Symlink Module Root
  • BZ - 2515385 - CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing
  • BZ - 2515386 - CVE-2026-70452 rsync: rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
  • BZ - 2515389 - CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options
  • BZ - 2515395 - CVE-2026-70456 rsync: rsync: Heap Out-of-Bounds Write via crafted argument list
  • BZ - 2515396 - CVE-2026-53793 rsync: rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
  • BZ - 2515403 - CVE-2026-70453 rsync: rsync: Denial of Service via Algorithmic Complexity
  • BZ - 2515409 - CVE-2026-70461 rsync: rsync: Information disclosure and denial of service via crafted files-from entry
  • BZ - 2515416 - CVE-2026-53802 rsync: rsync: Arbitrary File Read via Symlink Following
  • BZ - 2515417 - CVE-2026-53785 rsync: rsync: Arbitrary file write via path traversal in --relative mode
  • BZ - 2515419 - CVE-2026-53783 rsync: rsync: Directory escape via TOCTOU race condition in rrsync

CVEs

  • CVE-2026-53783
  • CVE-2026-53784
  • CVE-2026-53785
  • CVE-2026-53789
  • CVE-2026-53790
  • CVE-2026-53793
  • CVE-2026-53795
  • CVE-2026-53802
  • CVE-2026-53803
  • CVE-2026-70452
  • CVE-2026-70453
  • CVE-2026-70456
  • CVE-2026-70458
  • CVE-2026-70460
  • CVE-2026-70461
  • CVE-2026-70463
  • CVE-2026-70464

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
x86_64
rsync-3.1.3-28.el8_10.x86_64.rpm SHA-256: 849411e4458dbd95b2f374fa027da67ef493b6a5e66adfdc6e3719bc1aac33f3
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.x86_64.rpm SHA-256: fb04fb356b61d650a6e34559e7ec7560bd9936f4a89d388b8250fd9a749722ed
rsync-debugsource-3.1.3-28.el8_10.x86_64.rpm SHA-256: 4d3f625acf4c6c8060327964aef0c3764eab1ef382089b9d6771d3d8d6e8b1ea

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
s390x
rsync-3.1.3-28.el8_10.s390x.rpm SHA-256: 230697f2c44d1ceb42332ce964923bac9852188250172e6946cca07c8ab7c9f9
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.s390x.rpm SHA-256: 0a904bfab32252150c6139a5e77eaf349748c7a1bcc952c5f9a40a0f5ccd9ceb
rsync-debugsource-3.1.3-28.el8_10.s390x.rpm SHA-256: 1465cfcf456de47284862d36b314a9bfedaa22f009477a1e576a0d4d1b0f6521

Red Hat Enterprise Linux for Power, little endian 8

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
ppc64le
rsync-3.1.3-28.el8_10.ppc64le.rpm SHA-256: 8ab277f1a992c58f0ba62ae32e81d9bf4f4fa075c6f82ea4c70812f85bea041b
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.ppc64le.rpm SHA-256: e540bd7c2b1e239d3a1365d381323e06d19e1f5921e9b7c5cbf02e84d7b09a96
rsync-debugsource-3.1.3-28.el8_10.ppc64le.rpm SHA-256: ee4d0b9b5b114530dfc60e11be77ceb2eb293794b4a5420383002bc7185b7614

Red Hat Enterprise Linux for ARM 64 8

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
aarch64
rsync-3.1.3-28.el8_10.aarch64.rpm SHA-256: 6d9a063aae7fcd3886d0cef3b8f0df00b80c7045edf76588f2ed71384c02784c
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.aarch64.rpm SHA-256: dbe5613c7ab090bd8ab1c18997c529a7ed90cab67d5ef66f224e04145171d100
rsync-debugsource-3.1.3-28.el8_10.aarch64.rpm SHA-256: e1bfa8f11ce3135a47778b505412a90846dc33a3b2ee60cc2e8d1f4f10ee444f

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
x86_64
rsync-3.1.3-28.el8_10.x86_64.rpm SHA-256: 849411e4458dbd95b2f374fa027da67ef493b6a5e66adfdc6e3719bc1aac33f3
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.x86_64.rpm SHA-256: fb04fb356b61d650a6e34559e7ec7560bd9936f4a89d388b8250fd9a749722ed
rsync-debugsource-3.1.3-28.el8_10.x86_64.rpm SHA-256: 4d3f625acf4c6c8060327964aef0c3764eab1ef382089b9d6771d3d8d6e8b1ea

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
aarch64
rsync-3.1.3-28.el8_10.aarch64.rpm SHA-256: 6d9a063aae7fcd3886d0cef3b8f0df00b80c7045edf76588f2ed71384c02784c
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.aarch64.rpm SHA-256: dbe5613c7ab090bd8ab1c18997c529a7ed90cab67d5ef66f224e04145171d100
rsync-debugsource-3.1.3-28.el8_10.aarch64.rpm SHA-256: e1bfa8f11ce3135a47778b505412a90846dc33a3b2ee60cc2e8d1f4f10ee444f

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
ppc64le
rsync-3.1.3-28.el8_10.ppc64le.rpm SHA-256: 8ab277f1a992c58f0ba62ae32e81d9bf4f4fa075c6f82ea4c70812f85bea041b
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.ppc64le.rpm SHA-256: e540bd7c2b1e239d3a1365d381323e06d19e1f5921e9b7c5cbf02e84d7b09a96
rsync-debugsource-3.1.3-28.el8_10.ppc64le.rpm SHA-256: ee4d0b9b5b114530dfc60e11be77ceb2eb293794b4a5420383002bc7185b7614

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10

SRPM
rsync-3.1.3-28.el8_10.src.rpm SHA-256: 2b1fc591e05dc1adfcbc7b3bd08e74f95e3afaae40924590a8fcaddd8c49fb17
s390x
rsync-3.1.3-28.el8_10.s390x.rpm SHA-256: 230697f2c44d1ceb42332ce964923bac9852188250172e6946cca07c8ab7c9f9
rsync-daemon-3.1.3-28.el8_10.noarch.rpm SHA-256: 6e49f1fc7ba952c1a195178ddec535b96402cf5056ace652b8eafa30e41684d3
rsync-debuginfo-3.1.3-28.el8_10.s390x.rpm SHA-256: 0a904bfab32252150c6139a5e77eaf349748c7a1bcc952c5f9a40a0f5ccd9ceb
rsync-debugsource-3.1.3-28.el8_10.s390x.rpm SHA-256: 1465cfcf456de47284862d36b314a9bfedaa22f009477a1e576a0d4d1b0f6521

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility